SECURITY ALERT
The device was sealed.
The wallets were not.
On-chain analyst Specter says more than $86 million has been drained from hundreds of wallets linked to Ledger users, across Ethereum, TRON and Bitcoin. Ledger has not confirmed that figure, and no cause has been established.
What Ledger has confirmed is narrower. At 13:32 UTC on Friday its support account said it is “investigating reports of loss of funds from users in South East Asia who purchased products from a reseller named CryptoBillis”. “As a precaution,” it added, it has “asked CryptoBilis to pause all sales and shipments of Ledger devices”.
Ledger did not say its devices or software were compromised. It did not say the reseller did anything wrong.
What is reported, and by whom
At 12:24 UTC, Specter posted that it had traced theft addresses and found inflows from “more hundreds of victim wallets”, with total losses of “$86M+”. Specter later said it had not yet counted the number of wallets.
At 12:00 UTC, the researcher tanuki42 asked victims who had been drained to a list of TRON addresses to contact the SEAL 911 security group, putting that tally at more than $72 million and rising. Ledger’s main account reposted the call at 14:17 UTC.
The two figures are different tallies. Neither is a Ledger number.
BeInCrypto reported that three Bitcoin addresses in Specter’s thread hold about 211 BTC combined, and that the shop is a Malaysian seller that also operates in Indonesia and the Philippines. The Defiant reported that Ledger told buyers from the past 90 days to delay setup or move funds to a new device with a new seed phrase. We have not seen that advice in Ledger’s own post.
What we checked on-chain
One of the listed Bitcoin addresses is bc1qjqgwejnp8dc0x2938x9n9954hj97t82unx49dl.
At 14:16 UTC, mempool.space showed it had received about 92.5 BTC across 76 transactions, and had spent none.
The coins were sitting still. Where the Ethereum and TRON funds went is not yet clear.
Whether devices were altered before sale, recovery phrases were captured, or users were phished remains unestablished. Ledger said it will share updates as its investigation proceeds.
Protect yourself
- If you bought a Ledger from CryptoBilis in the past 90 days and have not set it up, do not set it up.
- If you have, check Ledger’s official support channels for its current guidance before moving funds, and move only to a device bought directly from Ledger, with a new seed phrase generated on it.
- Never type your recovery phrase into a website, app or support chat. Ledger says it will never ask for it.
- Buy hardware wallets from the maker or an authorised seller listed on its own site.
If a sealed box can’t be trusted, what exactly is a buyer supposed to check?
Related: Frogman wallet drain in Singapore ·
Related: What a crypto custodian does
Corrections and new evidence: [email protected]
This article is for information only and is not investment advice.
